Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation describes scripts that use environment variables, invoke shell commands, and access external networks, but the skill does not declare corresponding permissions. This creates a trust and review gap: an agent or operator may approve or run the skill without understanding that it can read secrets, contact RPC/transaction-service endpoints, and trigger blockchain-affecting operations.
